Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-38145
HistoryNov 23, 2022 - 2:15 a.m.

Design/Logic Flaw

2022-11-2302:15:00
PRIOn knowledge base
www.prio-n.com
3
silverstripe
xss
remote code execution
versioned history

0.001 Low

EPSS

Percentile

36.6%

Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page’s meta description and get it executed in the versioned history compare view.

CPENameOperatorVersion
frameworkge1.0.0
frameworklt1.11.1

0.001 Low

EPSS

Percentile

36.6%